Markets
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
Tech

Galaxy Flags Third Coldcard Wave as Losses Climb to 1,367 Bitcoin

The third sweep, spanning Friday to Saturday, split roughly 208 BTC across 293 separate P2WSH vaults — a shape change that made it far harder to trace than the first two.

By Oliver Bradford··3 min read
Galaxy Flags Third Coldcard Wave as Losses Climb to 1,367 Bitcoin

Key Points

  • The third sweep, spanning Friday to Saturday, split roughly 208 BTC across 293 separate P2WSH vaults — a shape change that made it far harder to trace than the first two.

Galaxy Research flagged a third wave of Coldcard sweeps early Sunday, taking the running total to 1,367 bitcoin drained from 4,585 addresses since the attack surfaced on 30 July.

At current prices the take is worth roughly $89 million. The first wave was clinical: 1,082.65 BTC pulled from 1,195 addresses inside a 41-minute window on 30 July. A second, smaller run the following day added 76.16 BTC across 1,478 addresses. The third, which stretched from Friday afternoon into Saturday morning UTC, drained around 208 BTC from 1,912 addresses and behaved unlike either predecessor.

Where the first two waves funnelled coins into a handful of collector addresses, the third split them across 293 separate P2WSH vaults. Pay-to-Witness-Script-Hash outputs let the spender defer any disclosure of what actually unlocks the coins until the moment they move, so the on-chain footprint reveals almost nothing about intent. That change alone made the third wave harder to trace in real time and broke the forensic pattern Galaxy used to sequence the first two.

Advertisement

728×90

Galaxy Research analysts have said they cannot determine whether the same operator is behind all three sweeps. The blockchain does not disclose coordination; only the shape of the activity does. What the sweeps do share is a root cause. Every affected address traces back to a firmware release Coinkite shipped for its Coldcard hardware wallet on 17 March 2021. That build introduced a change in how the device generated seeds, quietly redirecting key creation from the hardware random-number generator to MicroPython's deterministic fallback and sharply reducing the entropy of any wallet initialised on that firmware.

We covered the first wave last week: 594 bitcoin left 500 Coldcard wallets in a 25-minute sweep, when the initial burst set off a scramble at Coinkite to notify affected users. The number of drained addresses has since grown roughly ninefold and the drained-BTC total has more than doubled.

The stolen coins remain parked. Across the three waves, none of the tainted balances have been consolidated into exchanges or moved through mixers as of Sunday morning. That patience is its own signal. Whoever holds the keys is confident they can move funds at a moment of their choosing, not one dictated by mempool congestion or exchange listing risk.

For Coldcard owners, the operational question is simple and unpleasant. Any wallet seeded on the March 2021 build is exposed irrespective of how the coins have been custodied since. Rotating to a fresh seed generated on a patched firmware is the only remedy, and it must happen before the funds move, not after. Coinkite has published firmware updates and guidance for checking whether a device sits in the affected range; Galaxy has circulated tooling for third parties to test exposure at the address level.

There is a secondary consequence for the hardware wallet market. Coldcard's brand has always rested on the premise that a purpose-built, air-gapped device with published open-source firmware is the safest place for a bitcoin private key. That premise did not fail. A specific implementation did, five years ago, and the failure sat dormant until an operator with the patience to enumerate weak keys came looking. The industry's marketing has often blurred the distinction between hardware wallet and safe. This attack redraws that line in unforgiving detail.

The Humanity Protocol theft in June showed how a single custody mistake can consume tens of millions even in a supposedly hardened setup. The Coldcard sweeps are the same lesson at a different scale: the weakest link runs backward through time to whichever line of code was cut on which afternoon, and no amount of downstream discipline can rebuild the entropy that was never there.

The parked $89 million now sits in 293 vaults that will only reveal what secured them when the coins leave. That is the number to watch.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.